MZ Automation lib60870

Summary

MZ Automation lib60870 versions up to and including 2.4.0 are affected by an out-of-bounds read vulnerability. Successful exploitation can lead to a denial of service by crashing the parsing process. The affected critical infrastructure sectors include chemical, energy, and water and wastewater.

IFF Assessment

FOE

The article details a denial-of-service vulnerability that attackers could exploit, posing a risk to operational integrity.

Severity

8.2 High

The CVSS score of 8.2 (HIGH) is based on the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H, indicating an attack that is network-exploitable with low complexity, no privileges, no user interaction, and a high impact on availability.

Defender Context

This vulnerability affects critical infrastructure sectors and could lead to a denial of service, disrupting essential services. Defenders should prioritize patching or implementing compensating controls for any instances of MZ Automation lib60870 below version 2.4.1. Monitoring for unusual network traffic or parsing process crashes related to this software is also crucial.

Read Full Story →